|
288 | 288 | <getColumns value="True"/> |
289 | 289 | <getCount value="True"/> |
290 | 290 | <dumpTable value="True"/> |
291 | | - <db value="testdb"/> |
| 291 | + <db value="public"/> |
292 | 292 | <tbl value="users"/> |
293 | 293 | <excludeSysDbs value="True"/> |
294 | 294 | </switches> |
295 | 295 | <parse> |
296 | 296 | <item value="Title: AND boolean-based blind - WHERE or HAVING clause"/> |
297 | | - <item value="r'back-end DBMS: active fingerprint: PostgreSQL >= 8.4.0 and < 9.0.0'"/> |
| 297 | + <item value="r'back-end DBMS: active fingerprint: PostgreSQL >= 9.1.0'"/> |
298 | 298 | <item value="banner: 'PostgreSQL 9.1.11 on i686-pc-linux-gnu, compiled by gcc (Debian 4.7.2-5) 4.7.2, 32-bit'"/> |
299 | 299 | <item value="current user: 'postgres'"/> |
300 | 300 | <item value="current schema (equivalent to database on PostgreSQL): 'public'"/> |
|
330 | 330 | <getColumns value="True"/> |
331 | 331 | <getCount value="True"/> |
332 | 332 | <dumpTable value="True"/> |
333 | | - <db value="testdb"/> |
| 333 | + <db value="public"/> |
334 | 334 | <tbl value="users"/> |
335 | 335 | <excludeSysDbs value="True"/> |
336 | 336 | <answers value="do you want to perform a dictionary-based attack against retrieved password hashes=N"/> |
337 | 337 | </switches> |
338 | 338 | <parse> |
339 | 339 | <item value="Title: PostgreSQL AND error-based - WHERE or HAVING clause"/> |
340 | | - <item value="r'back-end DBMS: active fingerprint: PostgreSQL >= 8.4.0 and < 9.0.0'"/> |
| 340 | + <item value="r'back-end DBMS: active fingerprint: PostgreSQL >= 9.1.0'"/> |
341 | 341 | <item value="banner: 'PostgreSQL 9.1.11 on i686-pc-linux-gnu, compiled by gcc (Debian 4.7.2-5) 4.7.2, 32-bit'"/> |
342 | 342 | <item value="current user: 'postgres'"/> |
343 | 343 | <item value="current schema (equivalent to database on PostgreSQL): 'public'"/> |
|
373 | 373 | <getColumns value="True"/> |
374 | 374 | <getCount value="True"/> |
375 | 375 | <dumpTable value="True"/> |
376 | | - <db value="testdb"/> |
| 376 | + <db value="public"/> |
377 | 377 | <tbl value="users"/> |
378 | 378 | <excludeSysDbs value="True"/> |
379 | 379 | <answers value="do you want to perform a dictionary-based attack against retrieved password hashes=N"/> |
380 | 380 | </switches> |
381 | 381 | <parse> |
382 | 382 | <item value="Title: Generic UNION query (NULL) - 3 columns"/> |
383 | | - <item value="r'back-end DBMS: active fingerprint: PostgreSQL >= 8.4.0 and < 9.0.0'"/> |
| 383 | + <item value="r'back-end DBMS: active fingerprint: PostgreSQL >= 9.1.0'"/> |
384 | 384 | <item value="banner: 'PostgreSQL 9.1.11 on i686-pc-linux-gnu, compiled by gcc (Debian 4.7.2-5) 4.7.2, 32-bit'"/> |
385 | 385 | <item value="current user: 'postgres'"/> |
386 | 386 | <item value="current schema (equivalent to database on PostgreSQL): 'public'"/> |
|
416 | 416 | <getColumns value="True"/> |
417 | 417 | <getCount value="True"/> |
418 | 418 | <dumpTable value="True"/> |
419 | | - <db value="testdb"/> |
| 419 | + <db value="public"/> |
420 | 420 | <tbl value="users"/> |
421 | 421 | <excludeSysDbs value="True"/> |
422 | 422 | <answers value="do you want to perform a dictionary-based attack against retrieved password hashes=N"/> |
423 | 423 | </switches> |
424 | 424 | <parse> |
425 | 425 | <item value="Title: Generic UNION query (NULL) - 3 columns"/> |
426 | | - <item value="r'back-end DBMS: active fingerprint: PostgreSQL >= 8.4.0 and < 9.0.0'"/> |
| 426 | + <item value="r'back-end DBMS: active fingerprint: PostgreSQL >= 9.1.0'"/> |
427 | 427 | <item value="banner: 'PostgreSQL 9.1.11 on i686-pc-linux-gnu, compiled by gcc (Debian 4.7.2-5) 4.7.2, 32-bit'"/> |
428 | 428 | <item value="current user: 'postgres'"/> |
429 | 429 | <item value="current schema (equivalent to database on PostgreSQL): 'public'"/> |
|
487 | 487 | <getColumns value="True"/> |
488 | 488 | <getCount value="True"/> |
489 | 489 | <dumpTable value="True"/> |
490 | | - <db value="testdb"/> |
| 490 | + <db value="public"/> |
491 | 491 | <tbl value="users"/> |
492 | 492 | <excludeSysDbs value="True"/> |
493 | 493 | <answers value="do you want to perform a dictionary-based attack against retrieved password hashes=N"/> |
494 | 494 | </switches> |
495 | 495 | <parse> |
496 | 496 | <item value="Title: PostgreSQL inline queries"/> |
497 | | - <item value="r'back-end DBMS: active fingerprint: PostgreSQL >= 8.4.0 and < 9.0.0'"/> |
| 497 | + <item value="r'back-end DBMS: active fingerprint: PostgreSQL >= 9.1.0'"/> |
498 | 498 | <item value="banner: 'PostgreSQL 9.1.11 on i686-pc-linux-gnu, compiled by gcc (Debian 4.7.2-5) 4.7.2, 32-bit'"/> |
499 | 499 | <item value="current user: 'postgres'"/> |
500 | 500 | <item value="current schema (equivalent to database on PostgreSQL): 'public'"/> |
|
905 | 905 | <parse> |
906 | 906 | <item value="Title: AND boolean-based blind - WHERE or HAVING clause"/> |
907 | 907 | <item value="r'back-end DBMS: active fingerprint: SQLite 3'"/> |
908 | | - <item value="banner: '3.7.3'"/> |
| 908 | + <item value="banner: '3.7.13'"/> |
909 | 909 | <item value="r'Database: SQLite_masterdb.+1 table.+users'"/> |
910 | 910 | <item value="r'Database: SQLite_masterdb.+Table: users.+3 columns.+surname.+TEXT'"/> |
911 | 911 | <item value="r'Database: SQLite_masterdb.+Table: users.+5 entries.+luther.+nameisnull.+'"/> |
|
938 | 938 | <parse> |
939 | 939 | <item value="Title: Generic UNION query (NULL) - 3 columns"/> |
940 | 940 | <item value="r'back-end DBMS: active fingerprint: SQLite 3'"/> |
941 | | - <item value="banner: '3.7.3'"/> |
| 941 | + <item value="banner: '3.7.13'"/> |
942 | 942 | <item value="r'Database: SQLite_masterdb.+1 table.+users'"/> |
943 | 943 | <item value="r'Database: SQLite_masterdb.+Table: users.+3 columns.+surname.+TEXT'"/> |
944 | 944 | <item value="r'Database: SQLite_masterdb.+Table: users.+5 entries.+luther.+user agent.+'"/> |
|
970 | 970 | <parse> |
971 | 971 | <item value="Title: Generic UNION query (NULL) - 3 columns"/> |
972 | 972 | <item value="r'back-end DBMS: active fingerprint: SQLite 3'"/> |
973 | | - <item value="banner: '3.7.3'"/> |
| 973 | + <item value="banner: '3.7.13'"/> |
974 | 974 | <item value="r'Database: SQLite_masterdb.+1 table.+users'"/> |
975 | 975 | <item value="r'Database: SQLite_masterdb.+Table: users.+3 columns.+surname.+TEXT'"/> |
976 | 976 | <item value="r'Database: SQLite_masterdb.+Table: users.+5 entries.+luther.+user agent.+'"/> |
|
988 | 988 | <parse> |
989 | 989 | <item value="Title: SQLite > 2.0 AND time-based blind (heavy query)"/> |
990 | 990 | <item value="r'back-end DBMS: active fingerprint: SQLite 3'"/> |
991 | | - <item value="banner: '3.7.3'"/> |
| 991 | + <item value="banner: '3.7.13'"/> |
992 | 992 | </parse> |
993 | 993 | </case> |
994 | 994 | <case name="SQLite inline queries multi-threaded enumeration - all entries"> |
|
1049 | 1049 | <parse> |
1050 | 1050 | <item value="Title: AND boolean-based blind - WHERE or HAVING clause"/> |
1051 | 1051 | <item value="r'back-end DBMS: active fingerprint: Firebird 2.1 \(dialect 3\)'"/> |
1052 | | - <item value="banner: '2.5.0'"/> |
| 1052 | + <item value="banner: '2.5.2'"/> |
1053 | 1053 | <item value="current user: 'SYSDBA'"/> |
1054 | 1054 | <item value="r'current database: '/'"/> |
1055 | 1055 | <item value="current user is DBA: True"/> |
|
1088 | 1088 | <parse> |
1089 | 1089 | <item value="Title: AND boolean-based blind - WHERE or HAVING clause"/> |
1090 | 1090 | <item value="r'back-end DBMS: active fingerprint: Firebird 2.1 \(dialect 3\)'"/> |
1091 | | - <item value="banner: '2.5.0'"/> |
| 1091 | + <item value="banner: '2.5.2'"/> |
1092 | 1092 | <item value="current user: 'SYSDBA'"/> |
1093 | 1093 | <item value="r'current database: '/'"/> |
1094 | 1094 | <item value="current user is DBA: True"/> |
|
1127 | 1127 | <parse> |
1128 | 1128 | <item value="Title: Generic UNION query (NULL) - 3 columns"/> |
1129 | 1129 | <item value="r'back-end DBMS: active fingerprint: Firebird 2.1 \(dialect 3\)'"/> |
1130 | | - <item value="banner: '2.5.0'"/> |
| 1130 | + <item value="banner: '2.5.2'"/> |
1131 | 1131 | <item value="current user: 'SYSDBA'"/> |
1132 | 1132 | <item value="r'current database: '/'"/> |
1133 | 1133 | <item value="current user is DBA: True"/> |
|
1166 | 1166 | <parse> |
1167 | 1167 | <item value="Title: Generic UNION query (NULL) - 3 columns"/> |
1168 | 1168 | <item value="r'back-end DBMS: active fingerprint: Firebird 2.1 \(dialect 3\)'"/> |
1169 | | - <item value="banner: '2.5.0'"/> |
| 1169 | + <item value="banner: '2.5.2'"/> |
1170 | 1170 | <item value="current user: 'SYSDBA'"/> |
1171 | 1171 | <item value="r'current database: '/'"/> |
1172 | 1172 | <item value="current user is DBA: True"/> |
|
1191 | 1191 | </switches> |
1192 | 1192 | <parse> |
1193 | 1193 | <item value="Title: Firebird AND time-based blind (heavy query)"/> |
1194 | | - <item value="banner: '2.5.0'"/> |
| 1194 | + <item value="banner: '2.5.2'"/> |
1195 | 1195 | <item value="current user is DBA: True"/> |
1196 | 1196 | </parse> |
1197 | 1197 | </case> |
|
1221 | 1221 | <parse> |
1222 | 1222 | <item value="Title: Firebird inline queries"/> |
1223 | 1223 | <item value="r'back-end DBMS: active fingerprint: Firebird 2.1 \(dialect 3\)'"/> |
1224 | | - <item value="banner: '2.5.0'"/> |
| 1224 | + <item value="banner: '2.5.2'"/> |
1225 | 1225 | <item value="current user: 'SYSDBA'"/> |
1226 | 1226 | <item value="r'current database: '/'"/> |
1227 | 1227 | <item value="current user is DBA: True"/> |
|
1296 | 1296 | <tech value="E"/> |
1297 | 1297 | <getSchema value="True"/> |
1298 | 1298 | <dumpTable value="True"/> |
1299 | | - <db value="testdb"/> |
| 1299 | + <db value="public"/> |
1300 | 1300 | <tbl value="users"/> |
1301 | 1301 | <limitStart value="2"/> |
1302 | 1302 | <limitStop value="4"/> |
|
1314 | 1314 | <tech value="U"/> |
1315 | 1315 | <getSchema value="True"/> |
1316 | 1316 | <dumpTable value="True"/> |
1317 | | - <db value="testdb"/> |
| 1317 | + <db value="public"/> |
1318 | 1318 | <tbl value="users"/> |
1319 | 1319 | <limitStart value="2"/> |
1320 | 1320 | <limitStop value="4"/> |
|
1331 | 1331 | <threads value="4"/> |
1332 | 1332 | <tech value="B"/> |
1333 | 1333 | <dumpTable value="True"/> |
1334 | | - <db value="testdb"/> |
| 1334 | + <db value="public"/> |
1335 | 1335 | <tbl value="users"/> |
1336 | 1336 | <firstChar value="3"/> |
1337 | 1337 | <lastChar value="5"/> |
|
3216 | 3216 | <!-- End of file system access switches --> |
3217 | 3217 |
|
3218 | 3218 | <!-- Operating system access switches --> |
3219 | | - <!-- |
3220 | 3219 | <case name="MySQL web shell - command execution"> |
3221 | 3220 | <switches> |
3222 | 3221 | <url value="http://debian/sqlmap/mysql/get_int.php?id=1"/> |
3223 | 3222 | <tech value="B"/> |
3224 | 3223 | <osCmd value="id"/> |
3225 | | - <answers value="please provide additional comma separated file paths to=test"/> |
| 3224 | + <answers value="what do you want to use for writable directory=2,please provide a comma separate list of absolute directory paths=/var/www/test"/> |
3226 | 3225 | </switches> |
3227 | 3226 | <parse> |
3228 | 3227 | <item value="command standard output: 'uid="/> |
|
3234 | 3233 | <tech value="BU"/> |
3235 | 3234 | <osPwn value="True"/> |
3236 | 3235 | <msfPath value="/usr/local/bin/"/> |
3237 | | - <answers value="please provide additional comma separated file paths to=/var/www/test,do you want to overwrite it=Y,which connection type do you want to use=2"/> |
| 3236 | + <answers value="what do you want to use for writable directory=2,please provide a comma separate list of absolute directory paths=/var/www/test"/> |
3238 | 3237 | </switches> |
3239 | 3238 | <parse> |
3240 | 3239 | <item value="r'Sending stage.+Linux.+uid=.+www-data'" console_output="True"/> |
3241 | 3240 | </parse> |
3242 | 3241 | </case> |
3243 | | - --> |
3244 | 3242 | <case name="PostgreSQL User-Defined Function (UDF) injection - command execution (UNION)"> |
3245 | 3243 | <switches> |
3246 | 3244 | <url value="http://debian/sqlmap/pgsql/get_int.php?id=1"/> |
|
0 commit comments